
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32110 is a Server-Side Request Forgery (SSRF) vulnerability in SiYuan, a personal knowledge management system developed by b3log. The /api/network/forwardProxy endpoint accepts user-controlled URLs and forwards HTTP requests from the server without validating the destination, enabling authenticated users to reach internal networks, localhost, and cloud metadata services. All versions up to and including 3.5.9 are affected; the vulnerability was disclosed on March 11, 2026, and fixed in version 3.6.0. It carries a CVSS v3.1 base score of 8.3 (High) (GitHub Advisory, SiYuan Advisory).
The root cause is classified as CWE-918 (Server-Side Request Forgery). The vulnerable code resides in /kernel/api/network.go (lines 153–317), where the forwardProxy function extracts a user-supplied url parameter and only validates its format via url.ParseRequestURI() — it does not block requests to private IP ranges (e.g., 169.254.169.254), loopback addresses, or internal hostnames. The full HTTP response body and headers are returned to the caller, making this a "full-read" SSRF. Exploitation requires only valid authentication credentials (low privilege), no user interaction, and is reachable over the network with low attack complexity (SiYuan Advisory, GitHub Advisory).
Successful exploitation allows any authenticated user to perform internal network reconnaissance, enumerate internal services, and access cloud instance metadata endpoints (e.g., AWS/GCP/Azure IMDS at 169.254.169.254) to steal IAM credentials or other sensitive configuration data. The server acts as a trusted proxy, bypassing perimeter firewalls and network segmentation controls. Confidentiality and integrity impacts are rated High, with a Low availability impact, reflecting the risk of credential theft, data exfiltration, and potential lateral movement into internal infrastructure (SiYuan Advisory).
A proof-of-concept exploit is publicly documented in the GitHub Security Advisory, providing a complete step-by-step reproduction sequence requiring only authentication and a crafted HTTP POST request. Feedly threat intelligence classifies the PoC confidence as high, noting the advisory includes the exact request format and payload needed to exploit the vulnerability against a real SiYuan deployment. No in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.038% (0.06% per GitHub Advisory), indicating a currently low but non-negligible exploitation probability. The vulnerability is not listed in the CISA KEV catalog (GitHub Advisory, SiYuan Advisory).
siyuan=<value>)./api/network/forwardProxy endpoint is accessible.POST /api/network/forwardProxy HTTP/1.1
Host: <siyuan-host>
Cookie: siyuan=<authenticated-cookie>
Content-Type: application/json
Content-Length: 102
{"url":"http://169.254.169.254/metadata/v1/","method":"GET","headers":[],"payload":"","timeout":7000}169.254.169.254 (cloud metadata), 127.0.0.1/::1 (localhost), or RFC-1918 private IP ranges (10.x.x.x, 172.16–31.x.x, 192.168.x.x) that are not part of normal application traffic./api/network/forwardProxy with JSON bodies containing internal, loopback, or metadata service URLs; unusual response sizes from this endpoint indicating successful data retrieval./api/network/forwardProxy from user accounts that do not normally use this feature, especially with short intervals suggesting automated scanning of internal IP ranges (SiYuan Advisory).Upgrade SiYuan to version 3.6.0 or later, which addresses the vulnerability by implementing proper URL destination validation in the forwardProxy endpoint. As a network-level workaround, implement egress filtering on the host running SiYuan to block outbound connections to cloud metadata IP ranges (169.254.169.254) and internal RFC-1918 address spaces. Additionally, restrict access to the SiYuan instance to trusted users only and consider placing it behind a network boundary that limits exposure (GitHub Advisory, SiYuan Advisory).
The vulnerability was reported by security researchers ritikchaddha and neo-ai-engineer and disclosed via GitHub's coordinated vulnerability disclosure process. Brief community discussion was observed on Bluesky and Mastodon shortly after disclosure, and the advisory was picked up by several vulnerability tracking services including VulnDB, CVEFeed, and ENISA's EUVD. No major vendor statements or significant media coverage beyond standard vulnerability aggregation have been noted (SiYuan Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."